CVE Database
/

CVE-2008-1673

Back to search

CVE-2008-1673

Published: Jun 10, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

The asn1 implementation in (a) the Linux kernel 2.4 before 2.4.36.6 and 2.6 before 2.6.25.5, as used in the cifs and ip_nat_snmp_basic modules; and (b) the gxsnmp package; does not properly validate length values during decoding of ASN.1 BER data, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) a length greater than the working buffer, which can lead to an unspecified overflow; (2) an oid length of zero, which can lead to an off-by-one error; or (3) an indefinite length for a primitive encoding.

VendorProductVersions

n/a

n/a

affected
n/a

References

SUSE-SA:2008:047
vendor-advisory
x_refsource_SUSE
30000
third-party-advisory
x_refsource_SECUNIA
30658
third-party-advisory
x_refsource_SECUNIA
SUSE-SA:2008:038
vendor-advisory
x_refsource_SUSE
29589
vdb-entry
x_refsource_BID
SUSE-SA:2008:035
vendor-advisory
x_refsource_SUSE
SUSE-SA:2008:052
vendor-advisory
x_refsource_SUSE
FEDORA-2008-5308
vendor-advisory
x_refsource_FEDORA
32104
third-party-advisory
x_refsource_SECUNIA
30982
third-party-advisory
x_refsource_SECUNIA
30580
third-party-advisory
x_refsource_SECUNIA
20080611 rPSA-2008-0189-1 kernel xen
mailing-list
x_refsource_BUGTRAQ
linux-kernel-ber-decoder-bo(42921)
vdb-entry
x_refsource_XF
30644
third-party-advisory
x_refsource_SECUNIA
SUSE-SA:2008:048
vendor-advisory
x_refsource_SUSE
32103
third-party-advisory
x_refsource_SECUNIA
MDVSA-2008:113
vendor-advisory
x_refsource_MANDRIVA
1020210
vdb-entry
x_refsource_SECTRACK
MDVSA-2008:174
vendor-advisory
x_refsource_MANDRIVA
32759
third-party-advisory
x_refsource_SECUNIA
ADV-2008-1770
vdb-entry
x_refsource_VUPEN
31107
third-party-advisory
x_refsource_SECUNIA
32370
third-party-advisory
x_refsource_SECUNIA
31836
third-party-advisory
x_refsource_SECUNIA
USN-625-1
vendor-advisory
x_refsource_UBUNTU
DSA-1592
vendor-advisory
x_refsource_DEBIAN
SUSE-SA:2008:049
vendor-advisory
x_refsource_SUSE
SUSE-SR:2008:025
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now